Apache DolphinScheduler 3.4.3 fixes six authorization flaws
On 8 October 2026 Apache disclosed six authorization CVEs in DolphinScheduler, all fixed in 3.4.3. They include kubeconfig credential exposure to non-admin users (CVE-2026-71895), data source password disclosure (CVE-2026-71183), user account disclosure (CVE-2026-71896) and three cross-project bypasses. All require an authenticated account. Not in CISA KEV. No public PoC.
Published 8 Oct 2026
What happened
On 8 October 2026 the Apache DolphinScheduler project published six security advisories on its mailing list and on oss-security, all fixed in DolphinScheduler 3.4.3. The 3.4.3 release itself was published on GitHub on 6 September 2026, about a month before the disclosure. Every issue is an authorization flaw in the DolphinScheduler API: an authenticated user can read or change data that their role or project membership should not allow.
The two issues highlighted in the original post are CVE-2026-71895, which lets authenticated non-admin users retrieve administrator-managed Kubernetes configuration (kubeconfig) data containing credentials, and CVE-2026-71896, which lets authenticated users retrieve other users' account information through the user list-all endpoint and enumerate accounts. The "additional authorization issues" have their own CVE IDs: CVE-2026-71183 (data source connection details and passwords), CVE-2026-66082 (cross-project schedule and workflow-definition state changes), CVE-2026-66084 (cross-project task definition changes through the with-upstream endpoint) and CVE-2026-66087 (cross-project task instance stop and savepoint).
Who is affected
Apache lists all DolphinScheduler versions before 3.4.3 as affected for CVE-2026-71896, CVE-2026-71183, CVE-2026-66082, CVE-2026-66084 and CVE-2026-66087. For CVE-2026-71895, the advisory text says 3.2.0 before 3.4.3, while the advisory header and the CVE record's structured data say 3.1.0 before 3.4.3, so 3.1.x deployments should be treated as potentially affected. The fix is 3.4.3 for all six.
Each issue needs a valid DolphinScheduler login; none is described as unauthenticated. The highest risk is in multi-tenant or shared deployments where many users or teams have accounts, and in instances where administrators have stored Kubernetes cluster configuration or data source credentials. The real impact of CVE-2026-71895 depends on the privileges of the stored kubeconfig, as Apache notes.
What is confirmed
Apache's severity labels are important for CVE-2026-71895 and CVE-2026-71183, critical for CVE-2026-71896, and moderate for CVE-2026-66082, CVE-2026-66084 and CVE-2026-66087. Apache does not publish CVSS scores. CISA-ADP, shown on NVD, scores CVE-2026-71895 and CVE-2026-71183 at CVSS 3.1 7.1 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N) and CVE-2026-71896 at 6.5 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N). The three moderate issues have no score yet. The Apache CNA maps CWE-863 (Incorrect Authorization) for five issues. For CVE-2026-71895 the CNA record has no CWE and CISA-ADP maps CWE-862 (Missing Authorization).
The post's claims match Apache's text. For CVE-2026-71895, Apache says the exposed kubeconfig contains credentials that may allow direct authentication to the Kubernetes API, and that with cluster-admin or broadly privileged service-account credentials an attacker may read Secrets, create pods and persist in the cluster. For CVE-2026-71896, Apache says the endpoint returns account information without the required checks and may facilitate account enumeration. Apache credits several finders, including h1ei1, n0mi1k, meifukun, Wanxin Yin and Влад Рящиков (CVE-2026-71895), n0mi1k and lemi9090 (CVE-2026-71896), and Raphael Zanarelli (CVE-2026-71183). The other credits are on each CVE record.
None of the six CVEs is in the CISA KEV catalog. Where CISA-ADP has added SSVC data, it records exploitation as none. ThreatWire found no public proof-of-concept repository for any of them. The GitHub advisories (GHSA-vpj2-fvw3-8jgc, GHSA-q59v-7f6x-gwrc, GHSA-g89m-rq7v-96f2, GHSA-r995-5488-jh52, GHSA-26vh-p5jc-q2mg, GHSA-8x8j-rj29-7qph) are unreviewed and carry no score.
What is not confirmed
Apache does not report exploitation in the wild, and no source we checked does either. Apache does not say which account fields CVE-2026-71896 exposes. Some third-party pages list usernames, email addresses and roles, but that detail is not in the Apache advisory. The 3.4.3 release notes include several API permission changes, for example user list hardening, data source authorization list refinement, cluster query permission alignment and workflow project write permissions. Apache's advisories do not map individual pull requests to CVE IDs, and ThreatWire has not made that mapping. The exact lower bound for CVE-2026-71895 (3.1.0 or 3.2.0) is inconsistent within Apache's own advisory.
A third-party CVE aggregator labels the 7.1 score as a vendor score. NVD shows it as a CISA-ADP score, and Apache published only a textual severity.
What to do
Upgrade DolphinScheduler to 3.4.3 or later. Until you can upgrade, limit who holds accounts on the instance, review project membership and remove stale or shared accounts. Keep the web UI and API off the public internet.
Because CVE-2026-71895 and CVE-2026-71183 expose stored credentials, treat Kubernetes kubeconfig credentials and data source passwords configured in a pre-3.4.3 instance as potentially disclosed to any authenticated user. Rotate them, and prefer narrowly scoped Kubernetes service accounts over cluster-admin. Review Kubernetes API audit logs and database access logs for logins from unexpected sources. Review workflow schedule, release-state and task-definition changes for activity by users outside the owning project.
Sources: Apache DolphinScheduler advisories on lists.apache.org and oss-security (8 October 2026), the DolphinScheduler 3.4.3 GitHub release, NVD and CVE.org records with CISA-ADP data, GitHub advisories, and the CISA KEV catalog.
Related CVEs
- CVE-2026-66082 — DolphinScheduler cross-project schedule and workflow authorization bypass
- CVE-2026-66084 — DolphinScheduler task definition with-upstream project authorization bypass
- CVE-2026-66087 — DolphinScheduler task instance stop/savepoint project authorization bypass
- CVE-2026-71183 — DolphinScheduler data source authorization flaw discloses connection passwords
- CVE-2026-71895 — DolphinScheduler lets non-admin users retrieve Kubernetes credentials
- CVE-2026-71896 — DolphinScheduler user list authorization flaw exposes account information